Page MenuHomeFreeBSD

security/clevis: NEW PORT a pluggable framework for automated decryption
AbandonedPublic

Authored by dch on Sep 27 2023, 3:25 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Oct 19, 11:05 PM
Unknown Object (File)
Sep 23 2025, 8:13 PM
Unknown Object (File)
Sep 14 2025, 3:43 PM
Unknown Object (File)
Sep 13 2025, 2:21 AM
Unknown Object (File)
Sep 7 2025, 7:20 AM
Unknown Object (File)
Sep 4 2025, 11:21 AM
Unknown Object (File)
Aug 25 2025, 7:26 PM
Unknown Object (File)
Aug 13 2025, 1:16 AM
Subscribers

Details

Reviewers
None
Summary

Using security/tang as an example, it is possible for clevis to retrieve
a previously encrypted secret from the stateless tang server, without
the server having any knowledge of the secret.

Plugins, called pins, can be nested and combined in various ways,
from network presence, to Shamir secret sharing, and TPM2 hardware.

WIP - requires changes upstream.

Diff Detail

Repository
rP FreeBSD ports repository
Lint
No Lint Coverage
Unit
No Test Coverage
Build Status
Buildable 53745
Build 50636: arc lint + arc unit